Researchers: Oracle will address new Java flaw next month

Following an emergency patch late last month for vulnerabilities in Java 7, Oracle plans to address another recently discovered vulnerability in the platform, according to researchers who found the flaw. 

Security firm Security Explorations discovered the new vulnerability, which, when combined with other still-unpatched weaknesses in Java, could allow for a complete bypass of the Java Virtual Machine sandbox in the environment of the latest Java SE software.

Researchers reported the new vulnerability to Oracle a day after the database giant released its Aug. 30 out-of-band patch for holes affecting Java for the browser.

One of those exploits was added to the BlackHole crimeware kit and was being used in widespread attacks. Some researchers worry this vulnerability could meet the same fate, but so far, no reports of active attacks have emerged.

According to Security Explorations, Oracle confirmed the bug on Monday, and said it would address the issue in the Oct. 16 scheduled Java update.

An Oracle spokesman did not respond to a request for comment.

More in News

Event ticketing company hacked, at least tens of thousands affected

In the state of Maine alone, more than 22,000 Vendini customers were impacted.

Idaho State University to pay HHS $400K after investigation reveals shoddy security

The U.S. Department of Health and Human Services continues to ramp up its investigations of health care-related entities as a result of breaches.

Critical vulnerablilty discovered in industrial control product

The vulnerability was found in two programmable gateway devices often used by auto, food and manufacturing businesses in the United States. Meanwhile, a new study shows attacks against utility companies are growing.